Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.mpsl.elf

Overview

General Information

Sample name:Space.mpsl.elf
Analysis ID:1581303
MD5:6ed00a320457ddc794bad48f33fc5984
SHA1:25aabd4c30394e90b53ffab2848bc22db75c61c0
SHA256:c33e90da82794b4a558683f5d4bdf09467100db760c2e87d8a905c66566edabc
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581303
Start date and time:2024-12-27 10:42:13 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 47s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.mpsl.elf
Detection:MAL
Classification:mal68.evad.linELF@0/0@0/0
Command:/tmp/Space.mpsl.elf
PID:6246
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6220, Parent: 4331)
  • rm (PID: 6220, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.5bLSODjZds /tmp/tmp.NgFMncmzak /tmp/tmp.zS4YES22fh
  • dash New Fork (PID: 6221, Parent: 4331)
  • rm (PID: 6221, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.5bLSODjZds /tmp/tmp.NgFMncmzak /tmp/tmp.zS4YES22fh
  • cleanup
SourceRuleDescriptionAuthorStrings
6257.1.00007fc380400000.00007fc38042a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6248.1.00007fc380400000.00007fc38042a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6250.1.00007fc380400000.00007fc38042a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6246.1.00007fc380400000.00007fc38042a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.mpsl.elf PID: 6246Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xb7dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb7f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb804:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb818:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb82c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb840:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb854:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb868:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb87c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb890:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb8a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb8b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb8cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb8e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb8f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb908:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb91c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb930:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb944:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.mpsl.elfAvira: detected
Source: Space.mpsl.elfVirustotal: Detection: 44%Perma Link
Source: Space.mpsl.elfReversingLabs: Detection: 47%
Source: global trafficTCP traffic: 192.168.2.23:53260 -> 159.100.18.129:3778
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: Space.mpsl.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: 6257.1.00007fc380400000.00007fc38042a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6248.1.00007fc380400000.00007fc38042a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6250.1.00007fc380400000.00007fc38042a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6246.1.00007fc380400000.00007fc38042a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mpsl.elf PID: 6246, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mpsl.elf PID: 6248, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mpsl.elf PID: 6250, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mpsl.elf PID: 6257, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 6257.1.00007fc380400000.00007fc38042a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6248.1.00007fc380400000.00007fc38042a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6250.1.00007fc380400000.00007fc38042a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6246.1.00007fc380400000.00007fc38042a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mpsl.elf PID: 6246, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mpsl.elf PID: 6248, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mpsl.elf PID: 6250, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mpsl.elf PID: 6257, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal68.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6230/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6232/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6231/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6234/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6233/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6236/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6235/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1582/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/3088/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/230/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/232/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1579/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1699/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1335/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1698/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1334/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1576/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/2302/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/236/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/237/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/910/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6227/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6226/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/912/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6229/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6228/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/2307/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/918/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6241/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6240/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6246/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1594/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1349/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1344/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1465/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1586/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1463/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6238/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/801/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6237/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6239/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/1900/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/6252/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/491/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 6246)File opened: /proc/256/statusJump to behavior
Source: /usr/bin/dash (PID: 6220)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.5bLSODjZds /tmp/tmp.NgFMncmzak /tmp/tmp.zS4YES22fhJump to behavior
Source: /usr/bin/dash (PID: 6221)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.5bLSODjZds /tmp/tmp.NgFMncmzak /tmp/tmp.zS4YES22fhJump to behavior
Source: Space.mpsl.elfSubmission file: segment LOAD with 7.9456 entropy (max. 8.0)
Source: /tmp/Space.mpsl.elf (PID: 6246)Queries kernel information via 'uname': Jump to behavior
Source: Space.mpsl.elf, 6246.1.000055a9b231d000.000055a9b23c5000.rw-.sdmp, Space.mpsl.elf, 6248.1.000055a9b231d000.000055a9b23c5000.rw-.sdmp, Space.mpsl.elf, 6250.1.000055a9b231d000.000055a9b23c5000.rw-.sdmp, Space.mpsl.elf, 6257.1.000055a9b231d000.000055a9b23c5000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: Space.mpsl.elf, 6246.1.000055a9b231d000.000055a9b23c5000.rw-.sdmp, Space.mpsl.elf, 6248.1.000055a9b231d000.000055a9b23c5000.rw-.sdmp, Space.mpsl.elf, 6250.1.000055a9b231d000.000055a9b23c5000.rw-.sdmp, Space.mpsl.elf, 6257.1.000055a9b231d000.000055a9b23c5000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
Source: Space.mpsl.elf, 6246.1.00007ffeee427000.00007ffeee448000.rw-.sdmp, Space.mpsl.elf, 6248.1.00007ffeee427000.00007ffeee448000.rw-.sdmp, Space.mpsl.elf, 6250.1.00007ffeee427000.00007ffeee448000.rw-.sdmp, Space.mpsl.elf, 6257.1.00007ffeee427000.00007ffeee448000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/Space.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.mpsl.elf
Source: Space.mpsl.elf, 6246.1.00007ffeee427000.00007ffeee448000.rw-.sdmp, Space.mpsl.elf, 6248.1.00007ffeee427000.00007ffeee448000.rw-.sdmp, Space.mpsl.elf, 6250.1.00007ffeee427000.00007ffeee448000.rw-.sdmp, Space.mpsl.elf, 6257.1.00007ffeee427000.00007ffeee448000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581303 Sample: Space.mpsl.elf Startdate: 27/12/2024 Architecture: LINUX Score: 68 22 109.202.202.202, 80 INIT7CH Switzerland 2->22 24 159.100.18.129, 3778, 53260, 53262 DE-FIRSTCOLOwwwfirst-colonetDE Germany 2->24 26 2 other IPs or domains 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Antivirus / Scanner detection for submitted sample 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 Sample is packed with UPX 2->34 8 dash rm Space.mpsl.elf 2->8         started        10 dash rm 2->10         started        signatures3 process4 process5 12 Space.mpsl.elf 8->12         started        14 Space.mpsl.elf 8->14         started        16 Space.mpsl.elf 8->16         started        process6 18 Space.mpsl.elf 12->18         started        20 Space.mpsl.elf 12->20         started       
SourceDetectionScannerLabelLink
Space.mpsl.elf45%VirustotalBrowse
Space.mpsl.elf47%ReversingLabsLinux.Trojan.Mirai
Space.mpsl.elf100%AviraEXP/ELF.Agent.M.28
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.mpsl.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    159.100.18.129
    unknownGermany
    44066DE-FIRSTCOLOwwwfirst-colonetDEfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    159.100.18.129Space.x86_64.elfGet hashmaliciousUnknownBrowse
      Space.m68k.elfGet hashmaliciousMiraiBrowse
        Space.x86.elfGet hashmaliciousUnknownBrowse
          Space.ppc.elfGet hashmaliciousUnknownBrowse
            Space.mips.elfGet hashmaliciousUnknownBrowse
              109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
              • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
              91.189.91.43Space.m68k.elfGet hashmaliciousMiraiBrowse
                Space.mips.elfGet hashmaliciousUnknownBrowse
                  sh4.nn.elfGet hashmaliciousOkiruBrowse
                    mipsel.nn.elfGet hashmaliciousOkiruBrowse
                      powerpc.nn.elfGet hashmaliciousOkiruBrowse
                        db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                          RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                            RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                              RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                  91.189.91.42Space.m68k.elfGet hashmaliciousMiraiBrowse
                                    Space.mips.elfGet hashmaliciousUnknownBrowse
                                      sh4.nn.elfGet hashmaliciousOkiruBrowse
                                        mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                          powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                            db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                              RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                                RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                                  RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                                    db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                                      No context
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      CANONICAL-ASGBSpace.m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      Space.mips.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      arm6.nn.elfGet hashmaliciousOkiruBrowse
                                                      • 185.125.190.26
                                                      sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                      • 91.189.91.42
                                                      mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                      • 91.189.91.42
                                                      powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                      • 91.189.91.42
                                                      db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      RpcSecurity.arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      RpcSecurity.ppc.elfGet hashmaliciousUnknownBrowse
                                                      • 185.125.190.26
                                                      CANONICAL-ASGBSpace.m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      Space.mips.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      arm6.nn.elfGet hashmaliciousOkiruBrowse
                                                      • 185.125.190.26
                                                      sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                      • 91.189.91.42
                                                      mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                      • 91.189.91.42
                                                      powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                      • 91.189.91.42
                                                      db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      RpcSecurity.arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      RpcSecurity.ppc.elfGet hashmaliciousUnknownBrowse
                                                      • 185.125.190.26
                                                      INIT7CHSpace.m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      Space.mips.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                      • 109.202.202.202
                                                      mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                      • 109.202.202.202
                                                      powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                      • 109.202.202.202
                                                      db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      DE-FIRSTCOLOwwwfirst-colonetDESpace.x86_64.elfGet hashmaliciousUnknownBrowse
                                                      • 159.100.18.129
                                                      Space.m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 159.100.18.129
                                                      Space.x86.elfGet hashmaliciousUnknownBrowse
                                                      • 159.100.18.129
                                                      Space.ppc.elfGet hashmaliciousUnknownBrowse
                                                      • 159.100.18.129
                                                      Space.mips.elfGet hashmaliciousUnknownBrowse
                                                      • 159.100.18.129
                                                      boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 159.100.14.33
                                                      boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                      • 159.100.14.33
                                                      boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                      • 159.100.14.33
                                                      boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                      • 159.100.14.33
                                                      boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                                      • 159.100.14.33
                                                      No context
                                                      No context
                                                      No created / dropped files found
                                                      File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
                                                      Entropy (8bit):7.943062667584584
                                                      TrID:
                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                      File name:Space.mpsl.elf
                                                      File size:44'352 bytes
                                                      MD5:6ed00a320457ddc794bad48f33fc5984
                                                      SHA1:25aabd4c30394e90b53ffab2848bc22db75c61c0
                                                      SHA256:c33e90da82794b4a558683f5d4bdf09467100db760c2e87d8a905c66566edabc
                                                      SHA512:81ac48b0bd19a1fea4b662d21ea7e83c2c14b06defabcc031d57e96f34475ee2fd86b1dac99bc1d07e0451fd3f743cf829d8900a60d0d8e15473883cbfdeea52
                                                      SSDEEP:768:uQdzLFMbXkqyyxwmGFm3qsSPhkj96MiKrecs6cDtyO5XnQDgLZW2:9PmwqBOc31LNrecs6KtPXQDgLB
                                                      TLSH:2B13F14D97A1EA55C8CF5839B4CD13620E93B0C234271F9CA799ACCCA991C89BCC98B5
                                                      File Content Preview:.ELF........................4...........4. ...(...............................................C...C.....................UPX!d...................V..........?.E.h;....#......b.L#>g7.9f......1....F.....f.u.(L.X.Ak..8......~.Dl0..Wl../... ..il...$..........p?

                                                      ELF header

                                                      Class:ELF32
                                                      Data:2's complement, little endian
                                                      Version:1 (current)
                                                      Machine:MIPS R3000
                                                      Version Number:0x1
                                                      Type:EXEC (Executable file)
                                                      OS/ABI:UNIX - System V
                                                      ABI Version:0
                                                      Entry Point Address:0x1098d8
                                                      Flags:0x1007
                                                      ELF Header Size:52
                                                      Program Header Offset:52
                                                      Program Header Size:32
                                                      Number of Program Headers:2
                                                      Section Header Offset:0
                                                      Section Header Size:40
                                                      Number of Section Headers:0
                                                      Header String Table Index:0
                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                      LOAD0x00x1000000x1000000xac150xac157.94560x5R E0x10000
                                                      LOAD0xaffc0x43affc0x43affc0x00x00.00000x6RW 0x10000
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Dec 27, 2024 10:42:58.837618113 CET43928443192.168.2.2391.189.91.42
                                                      Dec 27, 2024 10:42:59.873605967 CET532603778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:42:59.993122101 CET377853260159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:42:59.993217945 CET532603778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:00.008881092 CET532603778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:00.128339052 CET377853260159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:00.128423929 CET532603778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:00.247993946 CET377853260159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:01.345141888 CET377853260159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:01.345654964 CET532603778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:01.345741034 CET532603778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:01.346208096 CET532623778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:01.465688944 CET377853262159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:01.465771914 CET532623778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:01.474613905 CET532623778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:01.594058990 CET377853262159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:01.594170094 CET532623778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:01.713745117 CET377853262159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:03.173580885 CET377853262159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:03.173846960 CET532623778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:03.173888922 CET532623778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:03.174416065 CET532643778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:03.181853056 CET377853262159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:03.181917906 CET532623778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:03.293859959 CET377853264159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:03.293993950 CET532643778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:03.294878006 CET532643778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:03.414288998 CET377853264159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:03.414416075 CET532643778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:03.533910990 CET377853264159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:04.468827009 CET42836443192.168.2.2391.189.91.43
                                                      Dec 27, 2024 10:43:04.645818949 CET377853264159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:04.645919085 CET532643778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:04.645977974 CET532643778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:04.646476984 CET532663778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:04.765990019 CET377853266159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:04.766108036 CET532663778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:04.766946077 CET532663778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:04.886378050 CET377853266159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:04.886454105 CET532663778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:05.005954027 CET377853266159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:05.745357990 CET532683778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:05.864861012 CET377853268159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:05.864921093 CET532683778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:05.869146109 CET532683778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:05.988558054 CET377853268159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:05.988614082 CET532683778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:06.004559994 CET4251680192.168.2.23109.202.202.202
                                                      Dec 27, 2024 10:43:06.079565048 CET377853266159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:06.079720020 CET532663778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:06.079720020 CET532663778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:06.080182076 CET532703778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:06.108062029 CET377853268159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:06.199889898 CET377853270159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:06.200339079 CET532703778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:06.201378107 CET532703778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:06.320827007 CET377853270159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:06.321033955 CET532703778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:06.440722942 CET377853270159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:07.170439005 CET377853268159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:07.170593023 CET532683778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.170823097 CET532683778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.171327114 CET532723778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.290787935 CET377853272159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:07.290879011 CET532723778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.291810989 CET532723778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.411300898 CET377853272159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:07.411498070 CET532723778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.530981064 CET377853272159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:07.574021101 CET377853270159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:07.574203014 CET532703778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.574203014 CET532703778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.574569941 CET532743778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.694380045 CET377853274159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:07.694499969 CET532743778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.695307016 CET532743778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.814780951 CET377853274159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:07.814939976 CET532743778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:07.934459925 CET377853274159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:08.596302032 CET377853272159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:08.596445084 CET532723778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:08.596482038 CET532723778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:08.596986055 CET532763778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:08.716440916 CET377853276159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:08.716545105 CET532763778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:08.717552900 CET532763778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:08.836998940 CET377853276159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:08.837086916 CET532763778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:08.956585884 CET377853276159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:08.957660913 CET377853274159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:08.957720995 CET532743778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:08.957827091 CET532743778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:08.958233118 CET532783778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:09.077652931 CET377853278159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:09.077811003 CET532783778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:09.972054958 CET532783778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:10.022227049 CET377853276159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:10.022425890 CET532763778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:10.022480965 CET532763778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:10.023163080 CET532803778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:10.092221022 CET377853278159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:10.092374086 CET532783778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:10.093343019 CET532783778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:10.142667055 CET377853280159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:10.142784119 CET532803778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:10.143997908 CET532803778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:10.212868929 CET377853278159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:10.213027000 CET532783778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:10.264806986 CET377853280159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:10.265022993 CET532803778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:10.332670927 CET377853278159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:10.384649992 CET377853280159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:11.454514980 CET377853280159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:11.454840899 CET532803778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:11.454978943 CET532803778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:11.455712080 CET532823778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:11.575145960 CET377853282159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:11.575423956 CET532823778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:11.576860905 CET532823778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:11.696327925 CET377853282159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:11.696615934 CET532823778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:11.817981958 CET377853282159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:12.837779999 CET377853282159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:12.837896109 CET532823778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:12.837939024 CET532823778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:12.838553905 CET532843778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:12.958080053 CET377853284159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:12.958158970 CET532843778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:12.959106922 CET532843778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:13.078573942 CET377853284159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:13.078679085 CET532843778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:13.198342085 CET377853284159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:14.309200048 CET377853284159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:14.309536934 CET532843778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:14.309667110 CET532843778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:14.310661077 CET532863778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:14.430133104 CET377853286159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:14.430433035 CET532863778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:14.431936979 CET532863778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:14.551388979 CET377853286159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:14.551583052 CET532863778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:14.671206951 CET377853286159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:15.689234972 CET377853286159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:15.689562082 CET532863778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:15.689665079 CET532863778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:15.690493107 CET532883778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:15.809968948 CET377853288159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:15.810225964 CET532883778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:15.811733961 CET532883778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:15.931233883 CET377853288159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:15.931555033 CET532883778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:16.051120043 CET377853288159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:19.058841944 CET43928443192.168.2.2391.189.91.42
                                                      Dec 27, 2024 10:43:20.102292061 CET532783778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:20.222126961 CET377853278159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:25.820854902 CET532883778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:25.940614939 CET377853288159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:26.231275082 CET377853288159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:26.231511116 CET532883778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:30.210752010 CET377853278159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:30.210937023 CET532783778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:30.210937977 CET532783778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:30.211760998 CET532903778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:30.331294060 CET377853290159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:30.331581116 CET532903778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:30.332973957 CET532903778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:30.452505112 CET377853290159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:30.452708006 CET532903778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:30.572328091 CET377853290159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:31.345220089 CET42836443192.168.2.2391.189.91.43
                                                      Dec 27, 2024 10:43:31.591912985 CET377853290159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:31.592243910 CET532903778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:31.592366934 CET532903778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:31.593209982 CET532923778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:31.712920904 CET377853292159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:31.713234901 CET532923778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:31.714664936 CET532923778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:31.834256887 CET377853292159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:31.834486961 CET532923778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:31.954266071 CET377853292159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:32.972800016 CET377853292159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:32.973212004 CET532923778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:32.973388910 CET532923778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:32.974201918 CET532943778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:33.093739986 CET377853294159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:33.094141960 CET532943778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:33.096002102 CET532943778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:33.215497971 CET377853294159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:33.215944052 CET532943778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:33.335668087 CET377853294159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:34.446697950 CET377853294159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:34.447014093 CET532943778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:34.447226048 CET532943778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:34.448244095 CET532963778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:34.567812920 CET377853296159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:34.568103075 CET532963778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:34.569854021 CET532963778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:34.689404011 CET377853296159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:34.689585924 CET532963778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:34.809155941 CET377853296159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:35.440759897 CET4251680192.168.2.23109.202.202.202
                                                      Dec 27, 2024 10:43:35.873949051 CET377853296159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:35.874336004 CET532963778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:35.874434948 CET532963778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:35.875653982 CET532983778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:35.995707989 CET377853298159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:35.996076107 CET532983778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:35.998265028 CET532983778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:36.118056059 CET377853298159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:36.118303061 CET532983778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:36.238207102 CET377853298159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:37.301230907 CET377853298159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:37.301597118 CET532983778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:37.301661968 CET532983778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:37.302666903 CET533003778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:37.422203064 CET377853300159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:37.422355890 CET533003778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:37.424145937 CET533003778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:37.543721914 CET377853300159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:37.544012070 CET533003778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:37.663718939 CET377853300159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:38.683125019 CET377853300159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:38.683243990 CET533003778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:38.683307886 CET533003778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:38.684171915 CET533023778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:38.803936958 CET377853302159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:38.804126024 CET533023778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:38.806274891 CET533023778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:38.925856113 CET377853302159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:38.926007986 CET533023778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:39.045629025 CET377853302159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:40.109700918 CET377853302159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:40.110006094 CET533023778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:40.110006094 CET533023778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:40.111128092 CET533043778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:40.230824947 CET377853304159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:40.231076956 CET533043778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:40.233021021 CET533043778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:40.352480888 CET377853304159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:43:40.352636099 CET533043778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:43:40.472189903 CET377853304159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:44:00.013343096 CET43928443192.168.2.2391.189.91.42
                                                      Dec 27, 2024 10:44:26.284523964 CET532883778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:44:26.404182911 CET377853288159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:44:27.141496897 CET377853288159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:44:27.141602039 CET377853288159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:44:27.141711950 CET532883778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:44:27.141711950 CET532883778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:44:30.277169943 CET533043778192.168.2.23159.100.18.129
                                                      Dec 27, 2024 10:44:30.396892071 CET377853304159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:44:30.681946039 CET377853304159.100.18.129192.168.2.23
                                                      Dec 27, 2024 10:44:30.682157993 CET533043778192.168.2.23159.100.18.129

                                                      System Behavior

                                                      Start time (UTC):09:42:56
                                                      Start date (UTC):27/12/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):09:42:56
                                                      Start date (UTC):27/12/2024
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.5bLSODjZds /tmp/tmp.NgFMncmzak /tmp/tmp.zS4YES22fh
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                      Start time (UTC):09:42:56
                                                      Start date (UTC):27/12/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):09:42:56
                                                      Start date (UTC):27/12/2024
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.5bLSODjZds /tmp/tmp.NgFMncmzak /tmp/tmp.zS4YES22fh
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                      Start time (UTC):09:42:58
                                                      Start date (UTC):27/12/2024
                                                      Path:/tmp/Space.mpsl.elf
                                                      Arguments:/tmp/Space.mpsl.elf
                                                      File size:5773336 bytes
                                                      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                      Start time (UTC):09:42:58
                                                      Start date (UTC):27/12/2024
                                                      Path:/tmp/Space.mpsl.elf
                                                      Arguments:-
                                                      File size:5773336 bytes
                                                      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                      Start time (UTC):09:42:58
                                                      Start date (UTC):27/12/2024
                                                      Path:/tmp/Space.mpsl.elf
                                                      Arguments:-
                                                      File size:5773336 bytes
                                                      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                      Start time (UTC):09:42:58
                                                      Start date (UTC):27/12/2024
                                                      Path:/tmp/Space.mpsl.elf
                                                      Arguments:-
                                                      File size:5773336 bytes
                                                      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                      Start time (UTC):09:43:04
                                                      Start date (UTC):27/12/2024
                                                      Path:/tmp/Space.mpsl.elf
                                                      Arguments:-
                                                      File size:5773336 bytes
                                                      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                      Start time (UTC):09:43:04
                                                      Start date (UTC):27/12/2024
                                                      Path:/tmp/Space.mpsl.elf
                                                      Arguments:-
                                                      File size:5773336 bytes
                                                      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9